SecPod

Learn Search

Search across all Learn content

← Back to Security Research
BlueMoon: The Exploit Kit Powering Multiple Spy Groups and Zero-Day Attacks

BlueMoon: The Exploit Kit Powering Multiple Spy Groups and Zero-Day Attacks

Sep 17, 2026By Pranav M Rao5 min read

Summary

BlueMoon is a modular exploit kit that chains two Chrome V8 vulnerabilities with a Windows kernel privilege-escalation flaw. A victim only needs to open an attacker-controlled link in a vulnerable Chromium-based browser for the chain to attempt browser code execution, escape V8 isolation, elevate privileges, inject into Chrome's broker process, and launch an operator-selected payload. BlueMoon is not a single malware payload; it is an exploitation framework that gives different operators a reusable path from a malicious webpage to code execution on a Windows endpoint. The kit was observed in campaigns attributed to or associated with four espionage-focused clusters: TA412, also tracked as APT31; UNK_LateNight; UNK_DoubleCheck; and UNK_QuietRacket. The downstream malware varied by operator, showing that BlueMoon functions as an access and payload-delivery layer rather than a fixed backdoor.

The impact depends on the operator. Observed campaigns delivered the GemStone browser-surveillance and credential-theft extension, ShadowPad, Rust-based loaders, DLL-sideloading chains, and custom malware. Successful compromise can expose browser cookies, active sessions, browsing activity, screenshots, credentials, and other information reachable from the infected endpoint. Because the exploit kit was adopted rapidly by several clusters, the same browser-and-Windows chain can lead to different post-exploitation behavior.

Background

Proofpoint first observed BlueMoon in TA412 activity on August 28, 2026. Within days, three other espionage-focused clusters were using variants of the same kit. Most of the observed activity had a suspected China nexus, but Proofpoint cautioned that some use remained unattributed and that access to BlueMoon might not be exclusive to China-aligned actors.

The two V8 vulnerabilities were patch-gap zero-days during the observed attacks: fixes were visible in public upstream Chromium source before corrected stable browser builds reached users. That gap gave exploit developers an opportunity to study the code changes and weaponize them. BlueMoon variants differed in packaging, obfuscation, landing pages, redirects, telemetry, and payloads, yet retained the same exploitation sequence and embedded components, strongly indicating a common underlying source.

TA412 used tailored lures involving internship requests and the AAS-in-Asia 2026 conference. Other clusters targeted US aerospace organizations, a Vietnamese manufacturing company, and entities in Singapore and Indonesia. Victims who opened a malicious link were shown a temporary loading page while exploitation was attempted and were then redirected to a legitimate website, reducing the chance that the failed or completed exploit would immediately raise suspicion.

Vulnerability Details

CVE Weakness EPSS Score CVSS Score
CVE-2026-85046 Type confusion in Chrome V8's optimizing JIT path 1.46% 8.8 High (CVSS v3.1)
CVE-2026-87491 Out-of-bounds write in V8 1.00% 8.8 High (CVSS v3.1)
CVE-2026-85880 CWE-122 heap-based buffer overflow in Windows ALPC 0.57% 7.8 High (CVSS v3.1)
BlueMoon's Windows exploit specifically checked builds 17763, 19041–19045, 20348, and 22000. Microsoft's advisory covers a broader affected-product set than the builds selected by the observed exploit.

Attack Methodology

  1. Targeted delivery: An operator sends a tailored phishing email containing a link to an attacker-controlled landing page.
  2. Exploit orchestration: The landing page loads BlueMoon's JavaScript launcher, which checks the browser environment, manages retries, and prepares three embedded components. p1 denotes the first payload, a reconnaissance DLL; p2 denotes the second payload, a Windows local privilege-escalation DLL; and pp denotes the position-independent process-injection shellcode launcher.
  3. Renderer exploitation: CVE-2026-85046 abuses V8 type confusion to produce address-disclosure and forged-object primitives, leading to arbitrary read and write access within the V8 heap.
  4. V8 sandbox escape: CVE-2026-87491 corrupts WebAssembly metadata and replaces compiled function bodies with shellcode from p1.
  5. Host reconnaissance: The reflectively loaded p1 DLL collects the Windows build, token integrity level, and kernelbase.dll version to decide whether the host is suitable for the kernel exploit.
  6. Privilege escalation: On a supported Windows build, p2 exploits CVE-2026-85880 to gain kernel read and write capabilities and enable SeDebugPrivilege.
  7. Broker-process injection: The pp launcher injects a CreateProcess stub and command line into Chrome's parent broker process, moving execution outside the renderer sandbox.
  8. Payload delivery: The default command uses curl to save an executable under %TEMP% and run it. The delivered payload depends on the operator and campaign.

Indicators of Compromise (IOCs)

The following defanged indicators were published by Proofpoint and cover the shared exploit kit plus representative infrastructure and payloads from all four observed clusters. Defenders should correlate them with phishing telemetry, browser activity, endpoint events, and the time of observation rather than treating a single historical indicator as conclusive evidence.

Cluster Indicator Type Description
TA412779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096dSHA-256driver-html.js, BlueMoon exploit JavaScript
TA4127d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288SHA-256ChromeUpdate.exe or msgbox.exe
TA412secboxes[.]comDomainExploit delivery and payload download domain
TA412msbenefit[.]comDomainExploit delivery and payload download domain
TA412extension-management-portal.centerfjdr658.workers[.]devHostnameGemStone extension command-and-control
UNK_LateNighta4a6a04d85eca8d584d939d2437c85a4f291207d8042f2ec002838e336b72ef5SHA-256Index.js, BlueMoon exploit JavaScript
UNK_LateNight295fc584f75e94108c9be945977db33ed80421f5d374eab188587c911dffd915SHA-256msgbox.exe
UNK_LateNightairproducts[.]inkDomainBlueMoon exploit delivery domain
UNK_LateNightms.checrity[.]comHostnameShadowPad command-and-control
UNK_LateNight79.133.56[.]90IP addressFallback ShadowPad command-and-control server
UNK_QuietRacketb34802a646fc4a8f07ffa09a5fda8bf7327446b22e3d7bb5163dafa1e2a8bb2bSHA-256Loader.js, BlueMoon exploit JavaScript
UNK_QuietRacketyhv41nji.workers[.]devHostnameBlueMoon exploit delivery
UNK_QuietRacketeduac.workers[.]devHostnameExploit delivery, payload download, and command-and-control
UNK_QuietRacketgetaiexo[.]comDomainCommand-and-control domain
UNK_DoubleCheckac6bbc4b1f1c62e308781329183a46e18f454c27e66bffa09f343b53ac622b69SHA-256font-01.js, BlueMoon exploit JavaScript
UNK_DoubleCheckvncdc.mailtbox.workers[.]devHostnameBlueMoon exploit delivery
UNK_DoubleCheckhomepage.brianwilli[.]comHostnamePayload download host
UNK_DoubleCheckfracons[.]comDomainCommand-and-control domain

MITRE ATT&CK Mapping

The following mapping is an analytical alignment of publicly reported BlueMoon behavior with the closest MITRE ATT&CK Enterprise techniques. BlueMoon does not currently have a dedicated MITRE software entry, and payload-specific techniques may not apply to every operator.

Technique ID Technique Name Tactic Observed BlueMoon Behavior
T1566.002Spearphishing LinkInitial AccessOperators sent tailored emails containing links to attacker-controlled exploit pages.
T1203Exploitation for Client ExecutionExecutionThe landing page exploited two V8 vulnerabilities to execute attacker-controlled code through the victim's browser.
T1082System Information DiscoveryDiscoveryThe p1 DLL collected the Windows version, build, token integrity level, and kernelbase.dll version.
T1068Exploitation for Privilege EscalationPrivilege EscalationCVE-2026-85880 was used to gain kernel read and write capabilities and elevate the renderer token.
T1055Process InjectionDefense Evasion / Privilege EscalationThe pp launcher injected executable code and a command line into Chrome's parent broker process.
T1105Ingress Tool TransferCommand and ControlThe default post-exploitation command used curl to retrieve and execute an operator-selected payload.
T1176Software ExtensionsPersistenceTA412 installed the GemStone Chromium extension and modified protected browser preferences so it would load persistently.
T1071.001Web ProtocolsCommand and ControlGemStone used HTTP-based registration, heartbeat, ingestion, screenshot upload, and command-polling endpoints.
T1113Screen CaptureCollectionThe GemStone extension supported screenshot collection and upload.
T1539Steal Web Session CookieCredential AccessGemStone requested browser cookie access and functioned as a browser-surveillance and credential-theft backdoor.

Visual Attack Flow

1Targeted phishing link

The victim receives a tailored email and opens a link to an actor-controlled landing page.

2BlueMoon JavaScript launches

The page checks the environment, orchestrates retries, and loads the browser exploit chain.

3CVE-2026-85046: renderer exploitation

V8 type confusion creates arbitrary read and write access inside the V8 heap cage.

4CVE-2026-87491: V8 sandbox escape

Corrupted WebAssembly metadata transfers execution to the embedded p1 shellcode and reconnaissance DLL.

5Host fingerprinting

BlueMoon checks the Windows build and token state to determine whether to run the kernel exploit.

6CVE-2026-85880: kernel privilege escalation

The p2 DLL obtains kernel read and write access and enables SeDebugPrivilege.

7Chrome broker-process injection

The pp launcher injects a CreateProcess stub into the parent broker process.

8Operator-selected payload

The chain downloads and runs GemStone, ShadowPad, a Rust loader, a DLL-sideloading package, or another campaign-specific payload.

Mitigation

  1. Update Chrome and Chromium-based browsers: Deploy Chrome 153.0.8010.36/.37 or later so both V8 vulnerabilities are remediated. Verify that Edge, Brave, Vivaldi, and other Chromium-based browsers have incorporated equivalent fixes.
  2. Apply Microsoft security updates: Install the applicable September 2026 Windows update for CVE-2026-85880. Migrate unsupported Windows systems to supported releases rather than relying only on endpoint controls.
  3. Block and hunt for published indicators: Search DNS, proxy, email, EDR, and firewall telemetry for the defanged infrastructure and hashes above. Use Proofpoint's complete indicator set for broader coverage.
  4. Detect the post-exploitation chain: Alert on Chrome renderer processes opening higher-privileged browser processes, remote-thread creation in Chrome's broker, and browser-initiated commands resembling curl -sS -o %TEMP%.
  5. Inspect Chromium profiles: Investigate unexpected browser termination followed by relaunch with --restore-last-session, unauthorized extension installation, modification of protected preference files, or the directory C:\Users\Public\stomp_ext.
  6. Contain confirmed infections: Isolate affected endpoints, preserve browser and EDR evidence, remove malicious extensions, rotate exposed credentials, revoke active web sessions, and rebuild the endpoint when kernel-level exploitation or process injection is confirmed.
  7. Reduce phishing exposure: Block newly registered and lookalike domains, detonate links in an isolated browser, and train high-risk users to report unexpected internship, conference, business-development, and supplier outreach.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

CVE Research

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

Oct 5, 2026

Open CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability
CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability

CVE Research

CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability

Oct 5, 2026

Open Open Door: Critical FortiMail Zero-Day Exploited to Write Arbitrary Files
Open Door: Critical FortiMail Zero-Day Exploited to Write Arbitrary Files

CVE Research

Open Door: Critical FortiMail Zero-Day Exploited to Write Arbitrary Files

Fortinet has disclosed CVE-2026-104286, a critical unauthenticated path traversal and NULL-byte handling vulnerability in FortiMail that allows arbitrary file writes via crafted HTTP or HTTPS requests. The issue is reported as exploited in the wild and is listed in the CISA KEV catalog. This article covers impact, affected versions, workarounds, fixed-build guidance, and indicators of compromise.

Oct 5, 2026

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026